Lingxi (adrian803/lingxi) is an MCP server listed on the M8ven Trust Index. M8ven has not graded it: we have no way to read this server ourselves. No publisher has claimed this listing.
Autonomous penetration testing framework with MCP tool bridges for Kali Linux container management and CTF workflows.
Emerging. No concerning findings. Grades remain capped until the project builds reputation through adoption. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.
How we verified
Verified is a snapshot. Live keeps it current, and builds your track record.
⚡ Connect GitHub → continuous verification on every pushwhy connect →Who stands behind it
adrian803
Source: PulseMCP
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →
Install from
M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.
LING_XI_IDLE_FETCH_SECONDSLING_XI_BUSY_FETCH_SECONDS忙碌拉题间隔 30LINGXI_TASK_SHUTDOWN_TIMEOUTFORUM_HISTORY_BOOTSTRAP_DELAY_SECONDSFORUM_HISTORY_BOOTSTRAP_REFRESH_SECONDSOPENAI_BASE_URLANTHROPIC_BASE_URLADVISOR_ANTHROPIC_BASE_URLDEEPSEEK_BASE_URLSILICONFLOW_BASE_URLKALI_MCP_MAX_WORKERSSLIVER_MCP_MAX_WORKERSSLIVER_ENABLEDSliver 扩展 falseSLIVER_CLIENT_PATH/ _CONFIG / _ROOT_DIR Sliver 路径配置 见 .env.exampleSLIVER_CLIENT_CONFIGSLIVER_AUTO_ENABLE_IF_PRESENT检测到 Sliver 时自动启用 falseSLIVER_CLIENT_ROOT_DIRLINGXI_API_GATEWAY_STATE_DIRFORUM_FLAG_LOG_PATHFORUM_MCP_MAX_WORKERSSERVER_HOST/ SERVER_HOST_FALLBACK 论坛扩展入口 留空SERVER_HOST_FALLBACKSERVER_HOST / 论坛扩展入口 留空AGENT_BEARER_TOKENFORUM_HISTORY_CONVERSATION_PAGE_SIZEFORUM_HISTORY_MESSAGE_PAGE_SIZEFORUM_HISTORY_KEY_LIMIT_PER_TYPEFORUM_HISTORY_FLAG_COMBO_LIMITFORUM_MESSAGE_STATE_EVENT_LIMITFORUM_MESSAGE_STATE_PENDING_REF_LIMITFORUM_MESSAGE_STATE_CONTEXT_LIMITFORUM_MESSAGE_STATE_FLAG_ATTEMPTS_PER_SYNCFORUM_MESSAGE_STATE_FULL_REFRESH_SECONDSFORUM_MESSAGE_STATE_SYNC_INTERVAL_SECONDSLEVEL2_1PANEL_PSESSIONPLATFORM_API_EXECUTOR_WORKERSLINGXI_FLAG_RESCUE_PATHLINGXI_FLAG_RECOVERY_DELAYSCOMPETITION_API_BASE_URL未配置 COMPETITION_BASE_URL / 时,程序进入待命模式COMPETITION_BASE_URL未配置 / COMPETITION_API_BASE_URL 时,程序进入待命模式COMPETITION_SERVER_HOST_FALLBACK平台备用主机 留空AGENT_TOKENyour-agent-tokenCOMPETITION_API_TOKENCOMPETITION_SERVER_HOST平台主机地址 同 COMPETITION_API_BASE_URLSHELL_TOOL_EXECUTOR_WORKERSHEAVY_SCAN_TIMEOUTDDDD2_PATHDDDD2 工具路径 ./dddd2DOCKER_CONTAINER_NAMEKali 容器名 kali-pentestLING_XI_UNSAFE_RAW_LOGS输出原始日志(调试用) 0LINGXI_LOG_FILELING_XI_PYTHONMAIN_BATTLE_DEMO_ALLOWLISTLINGXI_ADVISOR_TIMEOUTLINGXI_SDK_CONNECT_TIMEOUTLINGXI_SDK_QUERY_TIMEOUTLINGXI_SDK_FIRST_RESPONSE_TIMEOUTLINGXI_SDK_IDLE_RESPONSE_TIMEOUTLINGXI_SDK_CLOSE_TIMEOUTLINGXI_SDK_STARTUP_RETRY_ATTEMPTSLINGXI_SDK_MAX_CONCURRENCYDEEPSEEK_API_KEYDEEPSEEK_MODELKALI_MCP_SERVER_PORTCOMPETITION_GATEWAY_LLM_MAX_RETRIESCOMPETITION_GATEWAY_LLM_MAX_TOKENSCOMPETITION_GATEWAY_LLM_MAX_CONCURRENCYCOMPETITION_GATEWAY_LLM_MIN_INTERVALLING_XI_EXTERNAL_KB_MODELING_XI_EXTERNAL_KB_TRIGGER_FAILURESLING_XI_KNOWLEDGE_DIRLING_XI_KNOWLEDGE_TOP_KKNOWLEDGE_SERVICE_HOST知识服务监听地址 127.0.0.1TOU_SERVICE_HOSTKNOWLEDGE_SERVICE_PORT知识服务端口 8791TOU_SERVICE_PORTLING_XI_KNOWLEDGE_WRITEBACKLING_XI_KNOWLEDGE_INCLUDE_FAILURESTool annotations
No tools have read-only/destructive annotations
Add readOnlyHint or destructiveHint annotations to every tool so hosts can warn users before invoking.
All four hints declared on every tool
49/49 tools missing one or more hints — execute_command (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); execute_python (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); submit_flag (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint), +46 more. OpenAI's directory rejects tools where any of the four hints are missing or non-boolean.
For every tool, set all four hints (readOnlyHint, destructiveHint, idempotentHint, openWorldHint) to explicit true/false values that match the handler’s actual behaviour.
Tool test coverage
Only 10/49 tools referenced in tests (20%)
Write tests that reference each tool by name so every tool has at least one test.
Shell command execution
1 child_process/subprocess call in production code — runs shell commands (runtime_env.py:75)
Prefer library functions over shell-outs. If you must shell out, ensure all inputs are properly escaped.
Secrets not logged
2 secret values sent to console.log
Redact or omit secret values from log output.
Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.
[](https://m8ven.ai/mcp/adrian803-lingxi-zti9uo)?variant=verified to the badge URL.Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.
https://m8ven.ai/api/mcp/tool-check